The Doors Stayed Open. The Organisation Behind Them Was Running on Emergency IT.
The seven memorial sites operated by the Brandenburg Memorials Foundation remained open after ransomware disabled the organisation’s internal IT. Visitors could still enter Sachsenhausen, Ravensbrück and the foundation’s other locations while staff rebuilt systems and improvised alternative processes behind the scenes.
That continuity is important, but it should not be mistaken for a minor incident.
The attack broke normal email and telephone channels, disrupted bookings for educational programmes, encrypted systems and data, and forced a complete rebuild of the IT environment. More than a week after detection, the foundation said that full operational capacity would take longer than first expected and that it was establishing emergency operations.
The doors stayed open. The organisation behind them was still running on emergency IT.
What the foundation confirmed
The Brandenburg Memorials Foundation detected the incident on 5 August 2026 and disclosed it publicly on 11 August.
Attackers had gained access to internal IT and encrypted parts of the systems and data. The affected environment covered the head office and all seven memorial locations:
- Sachsenhausen Memorial and Museum;
- Ravensbrück Memorial Museum;
- the Death March Memorial in Below Forest;
- Leistikowstrasse Potsdam Memorial;
- the Memorial to the Victims of the Euthanasia Murders;
- Brandenburg-Görden Prison Memorial; and
- the Lieberose memorial site in Jamlitz.
The foundation disconnected internet and network connections, engaged an external IT-security provider recommended by Germany’s Federal Office for Information Security, notified Brandenburg’s data-protection authority and contacted the state police’s central cybercrime unit.
Its IT team began rebuilding and reinstalling the environment. The foundation said the rebuild was intended to ensure that an attacker could not regain access through the compromised systems.
The attackers left a text file asking the organisation to make contact, the familiar opening to a ransomware payment demand. Later reporting by the German Press Agency, citing a foundation spokesperson, said the attack was financially motivated and that the foundation did not pay.
No threat actor has been publicly identified.
The firewall claim is important but incomplete
On 18 August, DPA reported that the foundation’s spokesperson said the attackers had exploited weaknesses in the firewall. That is the most specific public description of the entry path.
It is not enough to identify a product, vulnerability or configuration error. Public reporting has not named a firewall vendor, model, software version, flaw or affected service. It is also not clear whether “weaknesses” refers to an unpatched vulnerability, exposed management access, weak authentication, a rule-set problem or a broader security gap at the perimeter.
Defenders should not turn that phrase into a technical attribution that the available evidence does not support.
The confirmed operational point is narrower: the foundation’s spokesperson linked initial access to the firewall layer, and the organisation is rebuilding the environment while forensic work continues.
Data theft is still being investigated
The foundation’s initial press release said it had to assume that attackers downloaded data. Its more detailed public guidance explained that forensic investigators were still determining whether data had actually been compromised and which systems were affected.
Potentially involved material included internal administrative information, contact and company details belonging to visitors and business partners, and agreements or documents connected with collaboration partners.
Those statements are not contradictory if read carefully. The organisation is treating exfiltration as a credible incident-response assumption, while the forensic scope remains unresolved.
That distinction should remain visible. It supports precautionary action without presenting an unverified data inventory as fact.
The foundation warned visitors, cooperation partners and suppliers to watch for phishing, spam and invoice fraud. If attackers obtained correspondence or partner records, they could construct messages that appear to continue a legitimate conversation or redirect a genuine payment to a different account.
For cultural and public institutions, this secondary risk can outlast the technical outage. Trust in the organisation’s name, staff and established relationships becomes part of the attacker’s inventory.
Open to visitors does not mean operationally normal
The foundation repeatedly stressed that visits remained possible without restriction. That was a meaningful continuity achievement.
Memorial sites are physical institutions. Exhibitions, grounds and scheduled public activity can continue even when central systems are unavailable. Staff can preserve the public mission through local knowledge, printed materials, manual processes and direct coordination.
But the same incident also disabled known email addresses and telephone lines, delayed enquiries and prevented normal handling of educational-programme bookings. A later local update said the business operation remained restricted even while registered educational formats, public tours and a commemorative event were still expected to proceed.
This is the difference between service availability and organisational capability.
The public-facing service may remain visible while staff lose the systems that coordinate bookings, partner communication, finance, records, scheduling and administration. The institution can look open from the outside while accumulating manual work, delayed decisions and recovery risk inside.
Emergency operations are a designed capability
The first public estimate suggested that systems might be available again within days. By 18 August, the foundation said full restoration would be a longer process and that the immediate goal was to establish emergency operations.
That change is not evidence of failure. Rebuilding a ransomware-affected environment safely often takes longer than restoring servers from backup. Teams must understand the entry path, establish trusted administration, reset credentials, validate backups, inspect dependencies and avoid reconnecting a foothold to the new environment.
The more useful question is whether emergency operations were designed before the attack.
A cultural institution should know how it will:
- publish trusted contact details when email and telephone systems fail;
- accept or defer group and educational bookings without the normal platform;
- preserve visitor and partner communications without creating uncontrolled copies;
- approve payments and changes to supplier bank details through an independent channel;
- continue scheduled ceremonies, tours and education work;
- maintain a verifiable public incident notice; and
- reconcile manual transactions after systems return.
These processes need named owners, paper or offline instructions and regular exercises. A continuity plan that exists only on the affected network is not a continuity plan.
Public institutions have asymmetric constraints
Memorials, museums, archives and foundations can hold sensitive information without having the security resources of a large commercial enterprise. Their data can include visitor enquiries, school bookings, donor and partner details, employment records, research correspondence and financial documentation.
They also have a strong obligation to remain accessible. Closing physical sites can harm education, remembrance and public trust, while restoring systems too quickly can increase the chance of reinfection or evidence loss.
That produces an asymmetric problem. Attackers need one workable route through a perimeter or identity control. The institution must defend ageing systems, specialist applications, distributed sites, external partners and a mission that cannot simply pause.
Security investment should therefore focus on reducing the consequences of a successful intrusion as well as preventing one:
- isolate public websites, booking systems, administration and archival environments;
- keep firewall and remote-access administration behind strong, separate identity controls;
- centralise logs somewhere an attacker in the local environment cannot erase them;
- maintain tested, offline or immutable recovery copies;
- predefine clean devices and communication channels for the crisis team;
- require independent verification for payment-detail changes; and
- exercise site-level continuity when the central office is unavailable.
The lesson is resilience without minimisation
The Brandenburg memorial sites remained open because their public mission was not completely dependent on the compromised network. That is resilience.
The incident was still organisation-wide. Staff lost normal systems, data may have been taken, partners face follow-on fraud risk and restoration became a multi-week process rather than a quick technical repair.
Both facts must be held at once.
Celebrating continued access should not minimise the burden on the people rebuilding the environment. Describing the severity should not erase the value of the continuity work that kept education and remembrance functioning.
The best security outcome is not merely that the doors stay open. It is that the institution can continue its mission through a tested emergency mode while rebuilding from a trusted foundation.
Sources and further reading
- Brandenburg Memorials Foundation: ransomware incident press release, 11 August 2026, publication time not stated
- Brandenburg Memorials Foundation: detailed incident guidance in English, 11 August 2026, publication time not stated
- Tagesschau and rbb24: Cyberattack on the Brandenburg Memorials Foundation, 11 August 2026 at 17:29 CEST
- DPA via Borkener Zeitung: Foundation establishes emergency operations after cyberattack, 18 August 2026, publication time not stated
- Meetingpoint Potsdam: Restricted operations and continued public events, 19 August 2026 at 17:01 CEST
Continue the series: European National Cyber & Digital Law Series index


